<!DOCTYPE html>
<html lang="en">

<head>
  <meta charset="UTF-8">
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  <title>Document</title>
</head>

<body>
<div id="test"></div>
<script>
  const divEle = document.getElementById('test')
  // 弹出xss
  divEle.innerHTML = '<img src="" onerror="alert(/xss/)"></img>'
</script>
</body>

</html>